So we’re just going to do safety after the funerals now? Is that what we’re doing? Super cool. I think that’ll work out great. Sike.
On September 3, 2026, Tesla put a car on the road that has no steering wheel. After the first, dozens of others followed. The age of the Cybercab is here, whether we like it or not. I think this is a massive failure of regulation, but I guess I’ll have to get to that point in a moment.
When I use the phrase “no steering wheel,” that’s probably doing a lot more for Tesla than they charitably deserve. What it really means is there is no plan B for this vehicle. No one can decide that this was a bad decision and then nudge the steering wheel in a different direction. There is no way to avoid an oncoming car. There’s no way for a human, to do things in a human environment, populated by other humans.
This is a vehicle that weighs 3,100 lbs, doing highway speeds.
I say this as a software engineer: Trusting novel automation software is a bad idea. It’s a bad idea in healthcare. It is a bad idea in accounting. It’s a bad idea with your law practice. In my Internet Menace curriculum, we call this AFD: actually fucking dangerous. The good news is it has butterfly doors, so that’ll be great, I guess?
There are currently 45 of these Cybercabs on Texas roads carrying passengers. On the same day, the National Highway Traffic Safety Administration opened something called an Audit Query, which is the federal government’s way of saying, “Hey, what the fuck are you doing?” Specifically, NHTSA wanted to understand how Tesla had certified a vehicle with no steering wheel and no pedals as compliant with Federal Motor Vehicle Safety Standards. You see, the FMVSS is a set of rules that are written around the idea that a car contains a person, and that person is operating a steering wheel and a combination of either two or three pedals to pilot a vehicle down public and private thoroughfares. You might know this as “driving.”
So you might be wondering: how was Tesla allowed to do this? Well, Tesla self-certified themselves. They didn’t find some legal loophole. This is just how our current automotive regulations work. Automotive manufacturers assess their own compliance, and then they attest to their own compliance, and then the federal government only investigates afterwards if something goes wrong.
This is an objectively fucking stupid way to do things.
In case you didn’t understand how I just framed everything up for you, here’s how that works in practice.
The first step is you build the car.
The second step is you certify your own car.
The third step is you put strangers in the car and drive the car around a city full of other people’s children.
The fourth step is the government sending you a polite letter asking you what you’re doing.
It does seem like this order of events is somewhat misaligned with public safety. We don’t do this with airplanes. We used to do this with airplanes, but we don’t anymore. Want to know why? Because a lot of people died. Dying is bad. If you are copying a safety framework that produces a lot of death and has historically produced a lot of death, that is a bad thing.
Let’s run this from the back. What are automotive self driving levels?
Before we can put legislation around anything, we have to agree on what “it” is. Right now, we lack the vocabulary to define what these vehicle safety levels are. Everything is just getting wrapped in marketing language. Marketing language, historically speaking, sucks when you’re attempting to build engineering standards behind it. People trying to sell you things are rarely trying to assure your safety, and this is by design.
The framework that we’ve all agreed to is called the Society of Automotive Engineers J3016, or SAE J3016. The most important thing to understand about SAE J3016 is the thing that everyone discussing self-driving cars gets wrong about self-driving cars. The levels are not describing capability; they are describing legal liability. These are not designed to describe what a car is good at. They are legal and functional requirements that are meant to describe who and what is responsible for what driving tasks at any given moment.
Once you understand that self-driving levels are legal frameworks and not engineering frameworks, everything else will make more sense.
So, with all that said, it’s important that you understand what the levels are and what they mean. After all, I can try to describe the rules of football to you, or you and I can just watch the game together.
Level 0 is your car warning you about things while you still do all the driving. Think about these as driver aids and enhancements — that can also include minor interventions that are temporary. Most cars you drive today that have been built within the past 10 years (or even 15 years) will have some of these driver’s aids. Blind spot warning, auditory and visual warnings, etc. These are something we would consider as level 0. Automatic emergency braking counts as a Level 0 system because it only intervenes momentarily and is not a sustained automation.
Level 1 automates a single axis of control. You’ve probably experienced this with adaptive cruise control that can handle speed while you steer. Lane Keep Assist can nudge the steering wheel while you handle the gas and the brake. It has one job on a single axis of control. You are still very much the driver.
Level 2 automates two axes simultaneously. This can mean steering and speed together continuously. Level 2 is where nearly every system you have actually heard of, currently exists. This includes: Volvo Pilot Assist, Tesla’s Autopilot, Tesla Full Self-Driving (Supervised), Ford Blue Cruise GM Super Cruise, BMW Highway Assistant, and a few others I’m probably forgetting. The important part to remember under SAE J3016 is that you are still defined as the driver of the vehicle. You are not a supervisor of the vehicle. You are not supposed to take a nap. You are not supposed to just think it’s going to take you from point A to point B without any assistance. You are responsible for driving the vehicle. If the vehicle crashes and you’re in the car, you are responsible, and you absorb all the legal liability.
Level 3 is where it gets complicated. At Level 3, within a defined set of conditions, the machine performs the entire driving task, and you are permitted to stop monitoring the road ahead. You can read email. You can doom scroll on TikTok. You can watch a movie. During operation of a Level 3 vehicle, you are not the driver. The manufacturer is asserting that its system is competent enough to own every driving task, and, critically, it can also detect its own approaching inability to continue, and hand control back to you. Mercedes-Benz has this system available with something they call Drive Pilot. The window for handing control back to you is 10 seconds.
At Level 3, the manufacturer of the vehicle is assuming legal liability.
Level 4 removes the human fallback entirely within the operational domain. There is no handover. If the system fails, the system is responsible for bringing the vehicle to a safe stop by itself. This is what Waymo does. Incidentally, this is also what the Cybercab is claiming to be. I’m going to get back to this claim in a second, because it seems a bit stunted, and likely driven by quarterly earnings reports and not public safety.
Level 5 is a vehicle that can drive anywhere, in any weather, and on any road, in any condition, without limits. Level 5 does not exist, and it’s important to note that it may never exist.
Of course, this has not stopped the automotive industry from inventing marketing terms. You might have heard things like “Level 2+.” Allow me an analogy. If your doctor said you could be prescribed Birth Control Pills or Birth Control Pills+, would you be confused? Do you see why inventing terms on top of things that already have meaning can be a bad idea?
The reason this is confusing and the reason we don’t do this is because that designation appears exactly fucking nowhere in SAE J3016. It is not a description of a level. It is a + that was attached to an existing level by a marketing department that wants the perception of Level 3 without the liability of Level 3. The fact that this is both permitted and also somewhat normal should tell you everything about the current regulatory environment regarding self-driving cars. The reason that self-attestation is a bad idea is something that we learned with Boeing to deadly effect.
The line between level 2 and level 3 is the most consequential line in self-driving technology. The reason it’s consequential is because it is where responsibility transfers from a person to a corporation. That is why almost every car company is staying firmly parked (yes, I intended the pun), at Level 2. While these systems are functionally far more capable than the label suggests, the attestation of Level 2 keeps the legal liability attached to the person who owns the car and not the corporation that made it.
As you read through the rest of this blog post, remember to keep that in mind. The line between level 2 and level 3 is not just about vehicle capability, but more importantly, it is about legal liability.
Now we need to talk about how the machine sees everything around it.
As a defense contractor, I think a lot about sensors. Optical sensors, thermal sensors, lidar, radar, microwave, you name it. I think about sensors because that’s the current UAS landscape. Sensors also exist on self-driving cars in many varieties and forms. Every discussion that we’re having about sensors on cars is a philosophical dispute that is downstream of a dispute about physics.
So let’s talk about sensors — specifically, the types of sensors we’re going to see commonly on cars.
Cameras are passive optical sensors. You know what the fuck a camera is, but now I’m going to explain it to you in more complex terms because being nuanced about what these cameras do and what their limitations are really matters right now. A camera is collecting ambient light and then producing an extraordinarily dense image that contains colors, textures, and symbols. It can tell the difference between a stop sign and a speed limit sign. It (sometimes) knows the difference between a paper bag and a rock, and nothing else in the world of sensors produces information that is that rich in context.
The upside to cameras is that they’re cheap, and they’re also scalable.
Cameras have the same limitations that your eyes have. The reason there is that they’re kind of the same sort of instrument. A camera can’t measure distance. More accurately, they can’t measure depth, and depth is inferred from objects and their relative size. It can be inferred from motion, or from stereo geometry, or alternatively from a neural network that has learned what size things usually are and then can place that size into space.
The problem with inference is that occasionally it’s very wrong. You’ve probably experienced this with your own personal AI assistant, like ChatGPT or Claude.
Cameras also have a finite dynamic range, so direct light can wash them out. Cameras also are photosensitive, and they need photons to operate, so camera performance degrades in darkness. Since we live on a planet where, on average, you’re going to experience about 12 hours of darkness a day, that means that there is a large period of operation where these cameras are less than ideal. Cameras can also be blocked by fog, water spray, dust, and just the general film of road grime that accumulates on lenses when you drive down the road.
What I mean to say is this: We have all experienced this exact same thing that is bad for optical cameras. You currently live on a planet that is illuminated by a nuclear fireball that spends a portion of each day sitting directly on the horizon while you are trying to aim your car down the road. So you crest a hill at 6:45 in the evening, and momentarily you go blind as you state directly at this nuclear fireball that is 8 light-minutes away. Cameras have that exact same experience.
So you may think that the assumption here is that in the name of safety, we must have more cameras on a car, but that’s not actually an assumption that is safe. We call that correlated failure. Redundancy does not mean having more sensors if those sensors will all fail for the same reason. Redundancy means having sensors that will fail for different reasons. So, having many cameras is not redundancy against glare. It just means there are nine ways for the system to fail with the same dynamic.
Okay, now it’s time for radar.
Radar transmits radio waves and measures what returns. Radar will give you range and, via Doppler shift, relative velocity, which is directly measured. Radar can penetrate fog, rain, and darkness with ease. Where radar falls short is angular resolution. Your automotive radar can tell you something is 100 ft away and closing at 30 mph, but it’s not good at telling you whether that thing is a stopped truck or an overhead bridge. Historically speaking, radar has an unnerving relationship with stationary objects.
This brings us to LiDAR.
LiDAR fires laser pulses and times their return. Think of it as radar’s laser-themed cousin. It produces a direct geometric measurement of the world, a point cloud, with resolution far exceeding radar. Lasers don’t need the sun to be up because lasers bring their own photons to the party. It does suffer from degradation in dense fog and heavy precipitation, but its type of degradation is different and also degrades differently than radar does. So, in theory, having optical cameras, radar, and LiDAR means you have a system that can be redundant in three different ways.
Ultrasonic sensors are for short-range action. Chances are your bumper already has these because that’s what makes parking sensors work. They’re great for parking lots and absolutely useless at any speed above 10 mph.
High-definition maps and precision localization are the backbone of every Level 3 and Level 4 system. If you’re a manufacturer, or third party data provider, you need centimeter-accurate resolutions of roads, bridges, signs, walkways, bike paths, bridges, overhangs, etc. When a car can ingest a centimeter-accurate model the world, it means the vehicle doesn’t need to actively deduce every single thing in its environment. Optical sensors, lasers and radar produce a picture, frame by frame, ingest by ingest, packet by packet. A pre-made, high precision world means less inferred ideas need to happen on the car’s local compute. Mercedes describes Drive Pilot as knowing ‘which lane it occupies to within a few centimeters.’ Waymo does not operate in cities it has not mapped. This is responsible, ethical operation. (And it is tied to their legal liability.)
Put all these ideas together, and we have something called “Sensor Fusion.” Maps, pre-existing notions about spaces and places, plus a variety of sensors… boom. It’s a good way to understand how to move a thing through a complex environment. It is imminently doable, but also expensive in initial capex, plus ongoing costs.
Additionally, there are still ways this system can fail. Sensor fusion can, and does, fail in unpredictable (and predictable) ways. Fusing camera, radar, and LiDAR, means the conditions that blind one instrument are conditions the others tolerate. Sun glare kills the camera and leaves lidar untouched. Dense fog degrades lidar and radar powers through mostly anything and everything — it just doesn’t know much about exactly where the thing is.
Meanwhile, we have Tesla’s “camera-only” bet, which I’ll do my very best to defend… before setting this dumpster on fire.
Tesla’s thesis works like this: Humans drive with two optical sensors and a brain, so basically “vision plus sufficient artificial intelligence is probably good enough, right?” Additionally, Tesla argues that sensor fusion introduces its own failure modes when instruments disagree, and the reasoning system has to arbitrate which sensor is correct. Lastly, LiDAR is expensive and also tends to introduce bulges and bubbles to vehicles. LiDAR is many things, but sensors are not exactly sleek.
When something is expensive, it also makes it more difficult to scale. This is why Tesla wants to make something cheap.
The Tesla thesis is wrong in a sad way. It is indeed true that humans have two eyes and a brain. It is true that humans have, objectively, a very high level of driving performance. Road fatalities from manned human vehicles have gone down every single year, per road mile, for the past 50 years. The problem with the thesis here is that we kill roughly 40,000 people on American roads every year using the human performance benchmark. Building a safety standard around “well people do it” is building on top of a safety foundation of 40,000 counterexamples that have died. This is a very stupid standard.
Additionally, this “disagreement problem” (which isn’t really a problem, just some bullshit Elon Musk wants to be true) about sensors and sensor fusion has already been solved in the aerospace industry, where triple-redundant, dissimilar sensors and voting logic have been standard practice since the 1980s.
Lastly, and perhaps most importantly, the strongest evidence against the optical sensor only thesis is not purely rhetorical. It’s mechanical. In 2024, NHTSA opened an investigation into Tesla’s FSD because of crashes that were caused by reduced visibility. These include sun glare, fog, and dust. One of these crashes killed a pedestrian. In March of 2026, NHTSA escalated this case to an engineering analysis, which is a more serious tier, and this covers 3.2 million vehicles.
The problem with this escalation is that we didn’t need it to begin with. Optical sensors alone are an extremely stupid decision. Period.
We should let grown-ups make these decisions.
The big problem about any conversation around automated driving is that the technology portfolios that are doing the most technically impressive work are the ones we hear the least about. Self-driving cars should be boring, and they shouldn’t require a lot of marketing speak. The kind of thing that we want these cars to do should be self-evident.
Example 1: Mercedes-Benz Drive Pilot
Tesla was not first to level 3. Mercedes-Benz was first to level 3. In 2023, Drive Pilot became the first certified SAE Level 3 system available in the United States, on the S-Class and the EQS, in Nevada and California. The conditions attached to it read exactly like lawyers wrote it, because they probably did: Mapped freeway segments only, in daylight, only in clear weather, limited-to-dense traffic, a lead vehicle required, and a top speed of 40 mph. In Germany, after a software update and recertification, it operates up to 95 km/h (about 59 mph) on the Autobahn network, in the right lane, following a vehicle, in good weather.
The Mercedes-Benz Level 3 system has more than 35 sensors on the S-Class: Cameras, radar, ultrasonic, lidar, plus a precision positioning system and continuously updated HD maps. Mercedes has stated that for Level 3 and above, LiDAR is not optional.
Let’s talk about what this combination actually represents. Mercedes built an extremely conservative “eyes-off-the-road” system and then wrapped it in the narrowest operational envelope that any engineer could write, and accepted legal responsibility for the driving scenarios inside that extremely narrow envelope. This is what taking level 3 liability seriously looks like. It looks slow, expensive, and boring. It means your marketing department has to say honest things like “in traffic on very specific freeways and only during the day when it is clear.”
Of course, this doesn’t exactly jump off the page in terms of marketing materials, which is why, for the 2026 S-Class in the U.S. market, Mercedes is not offering Drive Pilot. Instead, they’re offering this “Level 2++” system that I was previously mocking. It’s called MB.Drive Assist Pro. It works in more places, more of the time, and somewhat conveniently keeps the driver legally responsible rather than Mercedes-Benz. Functionally, it offers the same sensors and capabilities. It just means that Mercedes-Benz’s lawyers did not want to be responsible for anything that called itself Level 3. It also means that Mercedes-Benz was looking at the marketing language being put forward by Tesla and didn’t want to be beaten, especially because their vehicles had more capability but were operating within the constraints of a legal envelope.
This is what happens when marketing speak wins and engineers lose. The public gets noticeably less safe. Mercedes-Benz, as part of their announcement where they said they were rolling back their Level 3 system to a Level 2 system, said that the usable envelope was too narrow and that they had supplier problems. They then coded this in language, citing a partnership with Nvidia, and how they’re going to have “AI in their cars,” which is just the weakest shit ever. Blah blah blah. What the fuck does that even mean?
Let’s keep it real about what actually happened here. Mercedes-Benz tried to do it the right way, and because Tesla wasn’t following the rules, and they were doing it the wrong way, Mercedes-Benz couldn’t make the right thing profitable.
The company that did it the right way could not make the right way pay.
This is a tax on honest engineering, and when honest engineering means things are more expensive and less usable, what happens is dishonest operators will fill that space with hype and marketing speak and put the public in danger. We should be crediting Mercedes-Benz with building something carefully, pricing it at the actual price, restricting it in a way that operates safely, and then assuming the liability. They did all those things and found out that people will not pay for a system that only works in somewhat dense traffic under 40 mph on a dozen specific highways. Meanwhile, a competitor shipped a Level 2 system with an aspirational name to millions of vehicles and became the most-discussed automotive program on the planet.
If you need to understand why regulation is necessary, that entire picture is why. In an unregulated market, caution is a competitive disadvantage, and the people behaving responsibly are punished for it by the same customers who will be outraged when the reckless approach kills someone. When regulation is done well, it is a mechanism where the responsible choice is the easy choice and, in the case of safety, the survivable choice.
And now we can talk about my frenemy. BMW.
BMW runs the same two-track strategy. BMW Highway Assistant, the system you will find on an X5 or a 5 Series, is Level 2 hands-free on mapped divided highways with a driver-attention camera watching your eyes, and there is even a lane change you confirm by looking at the mirror. It is excellent and it is without any marketing speak — a partial system that expects you to be present and make decisions.
Separately, and almost completely off the menu in most places — BMW offers Personal Pilot L3 in Germany only, on certain 7 Series models, for 6,000 euros. (I don’t know how to make a euro on my keyboard, so I had to type that. Do Europeans get a euro on their keyboards instead of a dollar sign for the alternative function for the number 4? Now I’m curious.) It offers eyes-off driving up to 60 kmph on roads with structurally separated highways. It carries ultrasonic sensors, radar, and a 3D lidar unit. BMW made a point of noting it works in the dark. Which it can, because lidar does not need the sun… unlike other companies that can’t be honest about how cameras work.
Detroit Muscle… Memory? Ford BlueCruise.
BlueCruise, now at version 1.5, is Level 2 hands-free, but only inside pre-mapped and pre-qualified stretches of divided highway that Ford calls Blue Zones. It has an infrared driver-facing camera tracking your gaze and head position. Personally, I think that these zones should be designated by spheres on a map and referred to as “Blue Balls.” If you’re a Ford engineer reading this, please note my suggestion. On the F-150 it arrives as part of the Co-Pilot360 Active package. Step outside a Blue Zone and the system tells you, and hands the wheel back. Consumer Reports has repeatedly ranked it at or near the top of the field. It’s a good system when you’re inside a Blue Zone. But there are a lot of places that aren’t Blue Zones.
Somewhere in here I’m going to make the joke about the moving Cruising with Al Pacino. Now is the time. GM Super Cruise
This is probably the Al Pacino movie that you’ve never heard of. It’s called Cruising, where Al Pacino plays an undercover cop who infiltrates the local gay club scene as a leather daddy. 1980 was a weird time. I am willing to bet that if there is any movie that Al Pacino wishes he didn’t make, it is the one where he plays a leather daddy.
Let’s talk about SuperCruise. GM shipped the first mainstream hands-free system, geofenced to hundreds of thousands of miles of mapped, divided highways, with an infrared eye-tracking camera and a light bar that escalates from green to blue to a red. It is on the Tahoe (and Yukon), on some Cadillacs, and some Silverados. It is Level 2, and it makes no attempt to be a robotaxi.
Yup, we still got more ground to cover here. Volvo and Lucid.
Volvo’s Pilot Assist, on cars like the V90 Cross Country, is the most conservative system all of the automotive landscape. If you don’t follow automotive culture, Volvo’s entire brand is built on safety. Volvo’s institutional identity means that they gave away the patent to the three-point seatbelt in 1959. Volvo does not want to impress you with technology. They want you to get to your destination alive. Some of their vehicles have a combination of optical cameras and LiDAR, with physical location mapping. Curiously, they have very little about their self-driving capabilities published and tend to lean into driver assistance safety rather than automation. Of all the automakers that I cover today, Volvo is overwhelmingly cautious with their language and marketing.
Suffice it to say, I think all companies should be more like Volvo.
Lastly, I’ll just mention Lucid. Lucid put a lidar unit into the Air and Gravity, with its DreamDrive Pro hardware. This should also tell you where their engineers landed on the question of physics. Lucid engineers understand that optical cameras have limitations.
The pattern across every one of these companies is identical: Geofence the domain, monitor the driver’s eyes, publish the limits, keep the liability where the law already puts it, and choose a name that sounds like it’s helping you drive, rather than driving for you. Nobody at Ford named it Ford Self-Driving. Nobody at GM implied the Tahoe would come pick you up from the bar if you’re too drunk to drive.
Part Four: The shittiest approach possible.
Tesla’s Full Self-Driving is classified, by Tesla, as Level 2. It requires a supervising human in a seat.
I do not think the naming is a small thing. Names are how a technology enters public understanding, and once it enters your head the wrong way, it is nearly impossible to correct. In aviation, “autopilot” does not mean your pilot gets to go to sleep.
The current federal record is… not good for Tesla. NHTSA has an open preliminary evaluation covering roughly 2.88 million Tesla vehicles. NHTSA opened this evaluation after complaints and crash reports describing “FSD” entering intersections against red lights, failing to remain stopped, and crossing into oncoming traffic during lane changes. Driving into oncoming traffic is bad. This is the kind of thing that can happen when your optical sensor is blinded by the sun at exactly 6:30 in the afternoon.
Many of these accidents caused injuries. Some caused fatalities.
The agency has since extended the above inquiry to include behavior at railroad crossings. This is important because cars have significantly less mass than trains.
Separately, the reduced-visibility case escalated to an Engineering Analysis in March 2026, covering about 3.2 million vehicles.
In August 2025, a Miami federal jury returned a $243 million verdict in an Autopilot case, apportioning Tesla a share of fault for the design of the system, even though the driver was distracted.
And through all of this bullshit, the “robotaxi” program expanded. Austin in June 2025 with safety monitors aboard. Then Tampa, Miami, Dallas, Houston. The Bay Area, where the vehicles still carry monitors. Then, this month, Cybercabs with no steering wheel at all.
At the launch event, Elon Musk announced that its unsupervised robotaxi fleet had crossed “1 million cumulative miles.”
I want to just isolate for a moment that 1 million mile mark. It sounds like a lot, but unfortunately, this idea doesn’t survive when juxtaposed with how automotive safety miles are calculated.
American road fatalities occur at roughly one per 80 to 100 million vehicle miles traveled. That is the base rate you are trying to beat.
One million miles is approximately one percent of the distance you would need to travel to expect a single fatality by chance alone. A million miles without a fatality is not evidence of safety. It is not evidence of anything. If I flip a coin four times and get four heads, I have not defeated mathematics. A million miles sounds like a lot to people who don’t understand how road safety already works. Don’t get me wrong. I’m glad there wasn’t a fatality in those million miles, but also, statistically, there was roughly a 1-in-100 chance of a fatality happening during those 1 million miles.
For comparison: Waymo’s driving system passed 100 million miles in July 2025 and has been accumulating roughly two million miles per week. Tesla’s Texas Robotaxi fleet stood at about 420 vehicles as of this week, against nearly a thousand Waymo vehicles registered in the same state. And an analysis of Tesla’s Austin robotaxi operations reported 14 crashes across roughly 800,000 miles between June 2025 and February 2026, which works out to about one every 57,000 miles.
Look, I can’t tell you what is in Elon Musk’s heart because I don’t know, and I can’t know. With that said, I do think that Elon Musk is a sociopathic piece of shit and doesn’t have any regard for anyone but himself. I think he lies constantly, and I think he’s hopelessly immature and underdeveloped in ways that are difficult to describe. I would rather stick my dick into a box full of angry scorpions than have to interact with Elon Musk.
I also think his incentive structures are entirely fucked up. We’ll just focus on the incentive structures.
Tesla is a publicly traded company whose valuation is substantially detached from its car business, and substantially attached to a promise of autonomy. Milestones get announced at events. Analysts write notes about the future of autonomous cars. The stock moves when Tesla fanboys react to hype. I’m not crafting some crazy conspiracy theory. This is just how things happen.
In engineering, we call this a mechanism. A mechanism doesn’t require someone to be a villain in order to produce a bias towards an economic outcome.
The trouble is the mechanism behind that stock going up is a car without a driver, which is operating on a public road, and that public road contains an eight-year-old on a bike who did not buy the stock, does not care about stock, and deserves to be safe.
Waymo and the school bus problem.
As much as I’d like to end this entire blog post roasting the shit out of Elon Musk being an absolute fucking sociopath, I’m not going to do that. Because I try and at least do these things somewhat honestly.
Between the fall of 2025 and early 2026, Waymo, the company with the lidar, the radar, the cameras, the HD maps, the language of caution, and the hundred million miles of road tests, was caught repeatedly driving past stopped school buses.
Not just once. The Austin Independent School District documented roughly 20 incidents in a single school year, in which Waymo vehicles passed buses with red lights flashing and stop arms extended. In at least one, a Waymo drove past a bus moments after a student had crossed in front of it, while the student was still in the road. With the number of incidents that have happened, we are just lucky that no children have been hit by a Waymo and killed.
NHTSA opened a preliminary evaluation in October 2025. Waymo filed a voluntary recall in December, updating software on more than 3,000 vehicles. The school district reported that violations continued after the fix. In January 2026, the National Transportation Safety Board opened its own investigation.
I’d like to note something: These are just the ones with a paper trail. There is also the growing folk archive of the genuinely strange shit that happens, via YouTube, Reddit, TikTok, etc. The Waymo that drove into wet concrete at a construction site, the passenger circling a Phoenix parking lot inside a car that would not stop, the vehicles that clustered around a police standoff where police officers had to make sure sure passengers weren’t in the line of fire.
These are funny for about four seconds, and then you remember that “drove into wet concrete” and “drove into a group of children” are the same category of error with different consequences.
The record here proves what engineers already know. This is not safe. These decisions are being driven by a financial demand rather than a public demand.
From an engineering perspective, we know that perception is not the hard part anymore. The lidar saw the school bus. Of course it saw the fucking school bus. Lidar returns a dense geometric model of a large yellow rectangle forty feet away; there is no plausible universe in which the sensor missed it. What failed was behavior: The encoding of a social and legal rule about what a stop arm means, and the judgment about what a child might do next.
Waymo’s defense is that its vehicles are involved in dramatically fewer pedestrian injury crashes than human drivers. This is probably true. Fuck, I dunno, I can’t find any good data on people hitting kids next to stopped school buses. But it’s also the type of sentence that lawyers type when they want to make a point that is completely orthogonal to whether or not their vehicle fleet can reliably understand what the fuck a school bus is.
The sensor argument, which I have spent this entire blog post defending, is necessary, but it’s also insufficient from an engineering perspective. A good multimodal sensor array only buys you the right to have harder conversations. It is the start of the discussion we have about safety. The problem is marketing people think that engineering should be the end of the discussion about safety.
Which leads me to my actual conclusion, which, if you’re still here, I know took a long time to arrive at…
If the most careful operator in the self-driving, fully autonomous industry (with the best hardware, the most miles, and the strongest safety culture, and every single incentive to avoid PR disasters), still requires: Federal investigations, fleet-wide recalls, another federal investigation, public pressure from angry parents…
The answer will never be “Just trust these companies.”
The answer is a third-party institution that can oversee safety and has no fiduciary obligation to stockholders or any other financial entity.
By the way, we did this before.
I’m going to take you back to the Roaring Twenties for a second. In the 1920s, if you were flying U.S. airmail, you had one of the most dangerous jobs to ever exist. The U.S. Postal Service was losing pilots at a rate that, today, would have grounded the entire airline industry in a week. The response to this was the Air Commerce Act of 1926, which established federal authority over aircraft certification and pilot licensing.
It introduced a very simple principle: The pilot and the aircraft must be proven safe and airworthy before it carries the mail… let alone people.
Thirty years later, on the morning of June 30, 1956, TWA Flight 2 and United Airlines Flight 718 departed Los Angeles minutes apart and then collided over the Grand Canyon. All 128 people aboard both planes died, and their bodies were scattered across one of the emptiest landscapes on the U.S. continent. It was a truly bleak and horrifying scene.
The system that produced this scene was simple and ineffective. The system was basically this: The sky is big. Pilots should be able to avoid each other visually.
However, on the morning of June 30, 1956, the sky was not big enough, and two objects attempted to occupy the same space at the same time, which breaks the laws of physics and also produces mass death.
After an investigation into the accident, the Federal Aviation Act of 1958 was signed into law. This created the Federal Aviation Administration. This meant that we had positive control of airspace, nationwide radar coverage, assigned altitudes, and an air traffic system that assumed failure rather than hoping it wouldn’t happen. Shortly after came the National Transportation Safety Board. We also now have mandatory flight data recorders and no fault incident reporting. That means today, if there’s a near miss, pilots can report it without thinking it’s going to end their career.
Every single aviation safety measure was built upon a list of names. Those names were members of the public, adults and children alike, who paid the price of engineers assuming things were safe enough.
As a student of history, this is one of the most uncomfortable observations that I can make about any safety administration. Safety laws are not written in the future tense. Safety laws are written in the past tense.
The Air Commerce Act was a list of names paid for by the pilots of U.S. mail. The FAA happened because of every single person who died over the Grand Canyon. Automotive safety regulation in this country was paid for by the body counts of the millions of Americans who lost their lives prior to the mandates of seat belts.
Once upon a time, before 1968, cars were not mandated to be manufactured with seat belts. Additionally, it wasn’t until 1984 that every state in the nation had passed a law mandating that people wear them.
Anyway, what I want to note here is the asymmetrical way that we describe these problems.
An aircraft must be certified by the government before people are allowed to fly on it.
A car is certified by its own manufacturer, and the government only investigates after.
With self-driving cars, this is an intolerable situation.
The problem with self-certification is that self-driving cars rely upon behavior and not engineering specifications.
I’m not talking about a faulty fuel pump here. I’m talking about how the data from a statistical model that is trained on images and video that nobody outside these private companies has ever seen is being controlled. Our automotive safety systems and our automotive safety controls that are currently mandated by the government are insufficient to inspect software behavior.
By the time NHTSA has assembled enough incident reports to open a preliminary evaluation, the software version that caused them has been updated hundreds of times, and the company will tell you, (accurately), that you are investigating software that no longer exists.
We can’t keep running 1966 regulatory architecture against 2026 software failure modes.
So what exactly are we legislating then?
Being a critic without proposing some changes is just stupid. I have some suggestions.
1. End self-certification for driverless vehicles. If a vehicle is designed to operate with no human fallback, it should require affirmative federal approval before it carries a member of the public, just like the aviation model. I don’t want an exemption being granted. I want an positive approval, with a published evidentiary basis. If that slows deployment by two years, fine.
2. Mandate standardized, disaggregated, public safety data. Not “one million miles.” Miles by operational domain. Miles by weather and lighting condition. Disengagements by cause. Remote assistance interventions, which (by the way) are the most systematically underreported number in this entire industry. Contact events with narratives. Exposure-adjusted rates computed the same way, by every company, so that comparison is possible. Right now, every operator is collecting their own evidence with their own domains, their own data pipelines, and there is no standardization.
3. Publish the operational design domain in plain language. Put it on the window sticker, in the manual, and in the app. Where does this work? At what speeds? In what weather? In what light? What happens when it quits? Mercedes proved you can state these limits honestly and still sell the car. If being honest means you sell fewer cars, that’s okay.
4. Regulate the names. If a system requires a human to supervise it, it can never be marketed with a word that means it does not. This is ordinary consumer protection law applied to the most safety-critical purchase most Americans ever make. Several jurisdictions have already moved on this; it should be federal. There’s no such thing as “mostly edible” peanut butter… for a reason.
5. Create a vulnerable road user performance standard. School buses with stop arms deployed. Marked crosswalks. Cyclists. Children, who behave, from a machine learning perspective, like adversarial noise. Test against it, certify against it, and re-certify after any material software change. The Waymo school bus record is the reason we need this this, and Waymo was already doing their best. If you try your best and it’s still not working, you require regulation.
6. Treat over-the-air updates as design changes. Because they fucking are. If a change materially alters driving behavior, it triggers reporting obligations and, for driverless operation, re-validation. The current arrangement, where the vehicle’s behavior can be rewritten overnight while its certification remains untouched, is the most dangerous shit that I can imagine. (I haven’t even gotten to the malicious cybersecurity part where a hostile actor is able to push updates that remove security protocols just to fucking hurt people.)
7. Give an independent body real investigative authority. Subpoena power, mandated data preservation, guaranteed access to the sensor and decision logs from any incident, and public reports. The NTSB model exists. It works. The NTSB does not need to ask Boeing for permission to understand their aircraft. If the NTSB wants to look at a plane, they can go look at a plane.
8. Put the liability where the capability claim is. If you tell a customer they may take their eyes off the road, you own what happens next. Full stop. Mercedes accepted exactly this at Level 3, and that acceptance is precisely why Drive Pilot is so conservative. Liability is not a punishment. Liability is a mechanism that keeps engineers honest. Liability is a mechanism that makes sure marketing people don’t say things that are deliberately designed to mislead buyers. Liability is good. Liability means that if you fuck up, people can collect money when you decided to do the wrong thing.
9. Give cities a vote. Municipalities host these fleets, absorb the externalities, and dispatch the emergency services that end up managing a stalled robotaxi in an intersection, or the crashes that involve fatalities. Several states have preempted local authority entirely. That is backwards. At minimum, a city should have standing to demand data, request operational restrictions during school pickup hours, and reach a human being on the phone who can answer questions about why autonomous vehicles are doing the things they’re doing.
So then, when will self-driving and autonomous vehicles be ready for primetime?
I am a software engineer, and I specialize in machine learning. I should not be somebody who sounds like a luddite. There are about 40,000 people who die on American roads every year. The cause of most of those accidents is going to be impairment, distraction, excessive speed, and fatigue. Oh yes, also alcohol. Thankfully, self-driving cars can’t consume Coors Light.
Score one for the robots.
Anyway…
A mature autonomous fleet with comprehensive safety guardrails could plausibly be one of the greatest public health achievements this century. I’m going to be really clear about how I say this. No system will ever be perfect, but if we are able to reduce automotive fatalities from, say, 40,000 a year to 4,000 a year, then that means every decade we’re saving approximately… the population of Nashville, Tennessee.
The moral case for pursuing autonomous self-driving vehicles that can operate safely and surpass human beings in safety is a great idea.
The problem is, “eventually this is going to be good” is not an argument for “right now on the streets where my kids ride their bikes, unvalidated, self-regulated, and uncertified.”
It will be ready when the case for it is boring. It will not be a splashy launch event. There will not be strobe lights, and there will not be smoke machines. It should be mature, boring, and sober.
It will be ready when the data is standardized, public-facing, adjusted for exposure, and reviewed by people who don’t own stock in these companies. It will be ready when the failure modes are characterized rather than discovered in real time. It will be ready when a school district does not have to demand a federal agency investigate, because fleets of driverless cars are attempting to run over children exiting school buses. It is ready when the company shipping the product is willing to hold the liability, because that is the only claim that this entire industry cannot stand by right now.
I want this to be something that insurance companies are comfortable insuring.
To put it in the clearest terms I can, it is ready when you know your kids are safe to ride their bikes in your neighborhood and their community without fear of being struck by a driverless vehicle. As a machine learning engineer, as someone who intimately understands how sensor arrays work, I am deeply uncomfortable with how marketing people have led this discussion. I think it is fucking insane that we are allowing fleets of autonomous vehicles to run free in our cities around our children.
As the father of three children under the age of 6 years old, my children have the right to ride their bikes in safety, without fear of some Silicon Valley fuckheads snubbing their life because they wanted to realize some gains on their stock.
I did not opt in to this public beta. My children did not opt in to this public beta. My 81-year-old neighbor, who has crossed the same street every single day with her dog, did not opt in to this public beta.
I didn’t click a box saying I accept their risk. I didn’t click a box saying I understand that this robo taxi performs like shit in low-light conditions. And yet I’m being asked to accept their risk.
I am not a user. I am not a tester. I am not a validation set, nor are my children or my neighbors. We fucking live here.
Sources: NHTSA Office of Defects Investigation filings (PE25012, PE25013, EA26002, and the September 2026 Cybercab Audit Query);
Mercedes-Benz Group and Mercedes-Benz USA press materials on Drive Pilot;
WardsAuto reporting on the 2026 S-Class and Drive Pilot’s U.S. pause;
BMW Group press materials on Personal Pilot L3 and Highway Assistant;
Ford and GM materials on BlueCruise and Super Cruise;
Consumer Reports active driving assistance rankings;
Reuters and NTSB statements on the Waymo school bus investigation;
Austin Independent School District correspondence filed with NHTSA;
Bloomberg and Forbes coverage of the September 2026 Cybercab launch.
SAE J3016 defines the levels of driving automation.
